Privacy Policy Web / App
Introduction
Protecting your personal data is important to us. In this Privacy Policy, we inform you about the processing of your personal data in connection with your use of the Getsafe website and the Getsafe app, as well as about the data subject rights available to you.
For further information on the data processing carried out in connection with entering into an insurance contract on our website and in the Getsafe app, please see our Data Protection Information for Policyholders.
1. Who we are and how you can reach us
We,
Getsafe Digital GmbH
Waldhofer Str. 102
69123 Heidelberg
Email: [email protected]
are responsible for the processing of your personal data as soon as you visit our website or our app or contact us via the website, available at the URL https://www.hellogetsafe.com/, or via the app. Getsafe Digital GmbH (hereinafter: “we”, “us”, “our”) is part of the GETSAFE group (hereinafter: “GETSAFE”). Further information on all GETSAFE companies can be found at: https://www.hellogetsafe.com/de-de/impressum.
If you have any questions or suggestions regarding the processing of your personal data or your data subject rights, you can contact our Data Protection Officer at any time by email at [email protected], or send us a message by post to the address stated above marked “Datenschutzbeauftragter” (Data Protection Officer).
2. Personal data – information about you
Personal data is information that identifies you, such as your name. In addition, information that makes you identifiable only in combination with further details also constitutes personal data (e.g. your IP address). We divide the personal data we process about you into the following categories:
a. Access data
Access data is information required to enable the use of our website and online services. This includes in particular: browser type and browser version, operating system used, internet service provider, IP address of the requesting device, date and time of the server request, websites from which our website is accessed (referrer URL), and websites accessed by your system via our website.
b. Contact data
Contact data is information about you that is required in order to identify you and, where applicable, to contact you. This includes in particular: first and last name, address, email address, telephone number and date of birth.
3. What we use your personal data for
When you visit our website, we depend on processing your personal data in order to make our website available to you and to be able to interact with you.
a. When you visit our website
For the purpose of the technical provision of the website, it is necessary for us to process certain information automatically transmitted by your browser so that our website is displayed in your browser, you can use the website, and we can ensure IT security. This access data is recorded automatically each time our website is accessed and is stored in what are known as server log files.
For the duration of the session, the access data is stored in part in a cookie on your device and temporarily in a log file in our systems. In doing so, the IP address is anonymized on our server so that it is no longer possible to attribute it to an individual website visitor and therefore no longer possible to attribute it to a person; from that point on, there is no longer any personal reference. This access data is not processed for any other purposes.
The legal basis for the processing of personal data for the technical provision of the website is Art. 6(1) sent. 1 lit. f GDPR, whereby our legitimate interest arises from the purposes stated above.
b. App-specific features
When you use our app, we process additional data in order to provide you with the mobile functions and to ensure the security of the application.
If you merely create a user account via our app, we process the master data required for this purpose (name, email address, telephone number). We also collect information about your behaviour in the app as well as technical details about your device. This includes device IDs and advertising identifiers, push notification tokens, technical device data (operating system, app version, device model), your IP address, and your login credentials (email address and password in encrypted form).
Your master data is processed for the initiation or performance of your user contract on the basis of Art. 6(1) sent. 1 lit. b GDPR. Technical usage data is processed on the basis of Art. 6(1) sent. 1 lit. b GDPR in order to enable the download, the registration and the technical provision of the app. This processing is furthermore carried out on the basis of a legitimate interest pursuant to Art. 6(1) sent. 1 lit. f GDPR; our legitimate interest lies in ensuring IT security, stable app operation and the prevention of misuse.
Push notifications: We may send you messages as push notifications to your device. This is technically possible only if you allow the receipt of push notifications for our app in the settings of your device; you can withdraw this permission there at any time with effect for the future. For this purpose, we process the push token of your device. For service- and contract-related notifications (e.g. on the status of a claim report or on your contract documents), the legal basis is Section 25(2) no. 2 TDDDG as well as Art. 6(1) sent. 1 lit. b GDPR. For advertising push notifications, the legal basis is Section 25(1) TDDDG in conjunction with your consent pursuant to Art. 6(1) sent. 1 lit. a, Art. 7 GDPR, which you give separately in the app and can withdraw at any time with effect for the future; the permission in your device settings does not replace this consent. We delete the push token as soon as you deactivate receipt, withdraw your consent or uninstall the app. Dispatch takes place via Customer.io (see section 6.b); delivery to your device takes place technically via the push services of the operating system providers.
App usage analysis: In addition, we analyse how the app is used, in particular which functions are called up and at which points usage processes are abandoned. This analysis serves two purposes: the detection and correction of errors as well as the improvement of the app, and the prioritization of how we approach you, i.e. the decision as to which information and offers are relevant for you and when we contact you. The legal basis for this is Art. 6(1) sent. 1 lit. f GDPR; our legitimate interest lies in error detection and error correction, the improvement of our app and the prioritization of our customer communications. Attribution takes place via your user ID; device or advertising identifiers are not used for this purpose. You may object to processing for direct marketing purposes at any time without giving reasons (Art. 21(2) GDPR); otherwise, you may object on grounds relating to your particular situation (Art. 21(1) GDPR).
Further information on data processing in connection with insurance contracts and claims handling can be found in our specific Data Protection Information for Policyholders directly in our app.
c. When you contact us
For general contact enquiries, we offer you the option of contacting us via an email address provided on the website.
When contacting us by email, a valid email address as well as your first and last name are required so that we know who the enquiry comes from and can respond to it. Providing your address may be necessary in order to allocate your enquiry to one of our contact persons. We also collect contact data from you when you contact us by telephone or chat. To handle enquiries, we use customer service platforms as processors bound by instructions (see section 6.b).
The processing of data for contact by email is carried out on the basis of a legitimate interest pursuant to Art. 6(1) sent. 1 lit. f GDPR; our legitimate interest lies in answering and handling your enquiry, for which the storage and use of the contact data is necessary. If we are in a contractual relationship with you, or if contacting us serves the initiation of a contractual relationship on your part, the processing is carried out on the basis of Art. 6(1) sent. 1 lit. b GDPR.
If you transmit information about your health (health data) to us together with your enquiry, the legal basis for the processing of this data for the sole purpose of handling your matter is a consent pursuant to Art. 6(1) sent. 1 lit. a, Art. 7 and Art. 9(2) lit. a GDPR, which must be given by you separately. If you do not consent, we will delete your sensitive data without being able to handle the associated enquiry.
d. So that we can inform you about products and services
Newsletter and promotions: At various points on our website, we invite you to subscribe by email to information about products, services and promotions from GETSAFE. Your consent is given by actively clicking a checkbox (opt-in). The legal basis is your consent pursuant to Art. 6(1) sent. 1 lit. a, Art. 7 GDPR. You can withdraw your consent at any time with effect for the future, for example via the unsubscribe link in every email.
Advertising to existing customers: If you have taken out insurance with us, we will also inform you by email about our own similar products and services without separate consent. In this case, we obtained your email address in connection with the conclusion of your contract. The legal basis is our legitimate interest in direct marketing to our customers pursuant to Art. 6(1) sent. 1 lit. f GDPR in conjunction with Section 7(3) UWG (German Act Against Unfair Competition). You may object to this use at any time, for example via the unsubscribe link in every email or by message to the address stated in section 1 (Art. 21(2) GDPR). We inform you of this right to object in every email. On advertising push notifications in our app, see section 3.b.
e. Logging
Sign-ups for advertising communications by email are logged in order to be able to demonstrate the sign-up process in accordance with statutory requirements. This includes storing the time of sign-up and of confirmation as well as the IP address. Changes to your stored data by Customer.io are likewise logged (see section 6.b).
The legal basis for the processing of the access data for the purpose of logging is a legitimate interest pursuant to Art. 6(1) sent. 1 lit. f GDPR, arising from the necessity of properly documenting the declarations made and the measures taken and, where applicable, of being able to demonstrate them.
f. Measuring success
For emails we send, we measure whether and when they are opened and which links contained in them are clicked.
In doing so, we process the information as to whether and when an email was opened, which links were clicked, as well as technical details about the program used and the time of retrieval. Upon retrieval, your IP address is also collected by our service provider; it is not stored or analysed by us.
Legal basis: Art. 6(1) sent. 1 lit. a, Art. 7 GDPR on the basis of your consent, which we obtain together with your consent for direct marketing, as well as Art. 6(1) sent. 1 lit. f GDPR; our legitimate interest lies in verifying the deliverability of our emails and in making our communications understandable and relevant. You may object to the measurement at any time (Art. 21 GDPR). Independently of this, you can prevent it by deactivating the automatic loading of images in your email program.
g. When you visit our company pages on social media
In order to provide customers, partners or other interested parties with up-to-date information and to get in touch with you, in addition to our own website we operate company pages (in some cases also referred to as “fan pages”) on the following social networks: LinkedIn, Instagram, Facebook, TikTok, Reddit and YouTube.
When you visit our company pages on the social networks, the providers of the social networks process personal data about you for the purposes determined by them. The providers also determine how the data is collected and processed. The respective providers are responsible under data protection law for this type of processing.
We point out that the data processing by these providers takes place in part outside the European Economic Area. Insofar as the providers of the social networks make available to us aggregated user data or similar information about visitors, their behaviour during the visit and audience data relating to our company page, we are jointly responsible for this data processing together with the providers of the networks (Art. 26(1) GDPR). This means that the providers and we are each responsible for different sections of the data processing. You can find information on this here:
You can find the providers’ addresses in section 6.b. The respective privacy notices and the joint controllership agreements (for LinkedIn the Page Insights Joint Controller Addendum, for Meta the Page Insights Addendum, for TikTok the Joint Controller Terms) are available on the pages of the respective providers.
In addition, we process your personal data in the course of our own use of the company pages. This includes in particular responding to comments and personal messages from users that are directed to us via the company page, sharing third-party pages on our company pages, liking third-party posts, and tagging third-party pages.
The legal basis for the data processing is the legitimate interest pursuant to Art. 6(1) sent. 1 lit. f GDPR, whereby the legitimate interest arises from responding to the interaction expected and in part initiated by users, providing posts and content, and providing information about us.
4. When we use cookies and similar technologies
Detailed information about the cookies and similar technologies we use can be found on our website.
The storage of information on your device and access to such information are carried out on the basis of Section 25(2) TDDDG (German Telecommunications Digital Services Data Protection Act), insofar as this is strictly necessary in order for us to provide the service expressly requested by you. The subsequent processing of your data is carried out on the basis of our legitimate interest pursuant to Art. 6(1) sent. 1 lit. f GDPR in order to ensure the technical functionality and security of our website.
In all other cases in which the storage of and access to information from your device is not strictly necessary, the legal basis for this is Section 25(1) TDDDG in conjunction with your consent pursuant to Art. 6(1) sent. 1 lit. a GDPR, which you can give via our consent tool.
5. Duration of data storage
We store your personal data in identifiable form only for as long as is necessary for the respective purposes of collection (Art. 5(1) lit. e GDPR), unless statutory retention obligations exist (e.g. under commercial or tax law) or legitimate interests in storage for evidentiary purposes. In these cases, the duration of storage is determined by the statutory retention periods.
We also delete data collected for advertising purposes as soon as you withdraw your consent or object to advertising communications. We delete data from a contact enquiry as soon as your enquiry has been conclusively handled; if a business initiation or a contractual relationship arises from it, we generally store the data until that relationship has been settled.
6. With whom we share your personal data
a. With other GETSAFE companies
Insofar as this is necessary in order to fulfil the processing purposes stated above, we transfer personal data to other GETSAFE companies, namely:
GETSAFE GmbH, Waldhofer Str. 102, 69123 Heidelberg
Getsafe Broker GmbH, Europaplatz 9, 69115 Heidelberg
Insofar as personal data is additionally transferred for the handling of legal questions as well as of data protection and compliance matters within the group of companies, the legal basis is our legitimate interest in the central administration of intra-group tasks pursuant to Art. 6(1) sent. 1 lit. f GDPR (cf. Recital 48 GDPR).
Insofar as you use or request services of Getsafe Broker GmbH via our website or our app (insurance broker licensed under Section 34d(1) no. 2 GewO, German Trade Regulation Act), we transfer the personal data required for this purpose to Getsafe Broker GmbH. The legal basis is Art. 6(1) sent. 1 lit. b GDPR, since the transfer serves the initiation or performance of the brokerage relationship with you. Getsafe Broker GmbH is independently responsible under data protection law for the data processing within the brokerage relationship; its own privacy notices apply additionally in this respect. Conversely, insofar as we provide technical services on behalf of Getsafe Broker GmbH (in particular the operation of the app infrastructure), we act as its processor on the basis of an agreement pursuant to Art. 28 GDPR; the controller responsible for this processing is Getsafe Broker GmbH.
b. With technical service providers
Furthermore, we also transfer your data to external service providers, insofar as a legal basis under data protection law exists. We also use services whose providers are established in third countries (outside the EU) or transfer personal data there. The transfer is carried out primarily on the basis of an adequacy decision of the European Commission (Art. 45(1) GDPR), such as the EU-U.S. Data Privacy Framework for certified US recipients. Insofar as no adequacy decision exists or the provider is not correspondingly certified, we base the transfer on standard contractual clauses of the European Union (Art. 46(2) lit. c GDPR). The tables below set out, for each service, the purpose, the legal basis and, where a transfer to third countries takes place, the basis for that transfer. “DPF” refers to the EU-U.S. Data Privacy Framework (Art. 45(1) GDPR), “SCC” to the EU standard contractual clauses (Art. 46(2) lit. c GDPR).
The legal basis and the scope of the data processing may differ depending on the channel, i.e. depending on whether you use our website or our app. Where this is the case, we indicate it separately for the respective service.
Technical provision and consent management
Web analytics and app attribution
Advertising and marketing
Email dispatch and customer communication
For the handling of customer enquiries and the sending of messages, we additionally use further processors bound by instructions (Art. 28 GDPR), in particular a customer service platform (Dixa ApS, Denmark) as well as communication infrastructure for SMS, email and telephony services (Twilio Ireland Limited, Ireland; Mailgun Technologies, Inc. (Sinch), USA, safeguarded by the EU-U.S. Data Privacy Framework, Art. 45(1) GDPR). The technical delivery of push notifications to your device takes place via the push services of the operating system providers (Apple Push Notification service, Apple Distribution International Ltd., Ireland; Firebase Cloud Messaging, Google Ireland Limited, Ireland); in doing so, these providers process the push token of your device. Insofar as data is transferred to the USA in this context, this is carried out on the basis of the EU-U.S. Data Privacy Framework (Art. 45(1) GDPR).
Forms, application flows and appointment booking
Further processors
For the technical operation of our website and app, we use further processors bound by instructions (Art. 28 GDPR), in particular for cloud infrastructure and hosting (Amazon Web Services EMEA SARL and Google Cloud EMEA Limited, each with data processing in the EU) as well as for monitoring and error analysis (Datadog, Inc. and Functional Software, Inc. dba Sentry, each USA, safeguarded by the EU-U.S. Data Privacy Framework, Art. 45(1) GDPR, or in the alternative EU standard contractual clauses pursuant to Art. 46(2) lit. c GDPR).
c. With authorities and statutory recipients
Insofar as we are legally obliged to do so, we transfer personal data to the competent authorities (e.g. tax authorities, supervisory authorities or law enforcement authorities). The legal basis is Art. 6(1) sent. 1 lit. c GDPR in conjunction with the respective statutory notification obligation.
7. Your data protection rights
You have comprehensive rights in order to retain control over your personal data and to object to processing in certain cases.
a. Your rights vis-à-vis Getsafe
- A right to withdraw the consent you have given us (Art. 6(1) lit. a GDPR) to the data processing (Art. 7(3) sent. 1 GDPR). Following withdrawal, no further data processing will be carried out in the future. The lawfulness of the processing carried out on the basis of the consent up until the withdrawal is not affected (Art. 7(3) sent. 2 GDPR).
- A right to information as to whether we process data about you. If we process data about you, you have the right to obtain information about the nature and circumstances of the data processing (Art. 15(1), (2) GDPR).
- A right to rectification of your data if it is stored incorrectly or is no longer up to date (Art. 16 GDPR).
- A right to erasure of your data (Art. 17 GDPR) if it is no longer necessary for the original purposes, you withdraw your consent, a justified objection exists or the data was processed unlawfully. This also applies if the erasure is necessary in order to fulfil a legal obligation or if the data was collected in connection with information society services. If statutory retention obligations exist that prevent immediate erasure, your data will instead be blocked.
- A right to restriction of processing if you are of the opinion that the stored data is not correct, that the processing is unlawful, that the data is no longer needed for its purpose, or if you have lodged an objection (Art. 18(1) GDPR).
- A right to transfer of your data in the form of a digital copy (Art. 20 GDPR) if you have consented to the data processing (Art. 6(1) lit. a GDPR) or if it is based on a contract existing between us (Art. 6(1) lit. b GDPR).
- A right to object to the processing of your data on the basis of legitimate interests (Art. 21(1) GDPR), provided that grounds relating to your particular situation exist. We will then refrain from the processing, unless we can demonstrate compelling legitimate grounds that override your interests. If the processing is carried out for direct marketing purposes, you have a right to object at any time without giving reasons (Art. 21(2) GDPR).
If you would like to submit a data subject request or exercise your rights, you can contact us at any time by email using the contact details stated in section 1.
b. Your right to contact a supervisory authority
The protection of your data is very important to us. Should something nevertheless not be to your satisfaction, please contact us. You can find the contact details for this in section 1 of this Privacy Policy. You also have the right to lodge a complaint with a supervisory authority (Art. 77(1) GDPR). The supervisory authority responsible for Getsafe is:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg
Lautenschlagerstraße 20, 70173 Stuttgart
Postal address: Postfach 10 29 32, 70025 Stuttgart
Email: [email protected]
8. Obligation to provide data
There is generally no obligation to provide the data, but provision may be necessary in order to be able to make full use of certain functions of our website (e.g. price calculation).
9. Automated decision-making
No decision based solely on automated processing (including profiling) takes place which produces legal effects concerning you or similarly significantly affects you (Art. 22(1) and (4) GDPR).
As of: July 2026